Cybersecurity Compliance Analyst

9 ore fa

Varese, Lombardia, Italia Docebo Tempo pieno
Overview

As Cybersecurity Compliance Analyst, you safeguard Docebo’s security posture and bolster customer trust. You translate complex compliance frameworks into practical actions that support sales and legal teams. You lead audits and CAPs, collaborating across GRC and legal to map requirements to standard processes. You’ll automate workflows with AI tools and publish up-to-date compliance insights for customers. This role offers the chance to shape security in a fast-growing SaaS platform and enable enterprise learning at scale.

Retribuzione / Benefits
  • ESPP at 15% discount
  • health benefits
  • paid vacation days
  • Docebo Days, two company-wide
  • floating holidays for cultural celebrations
  • birthday off
Responsabilità
  • Respond to prospect and customer security requests, and provide clear compliance posture in RFIs/RFQs
  • Drive correctives actions by addressing customer security questionnaires and creating CAPs
  • Collaborate with legal to review Customer Agreements and Data Processing Addendums, mapping client needs to standard processes
  • Lead and support annual customer audits, coordinating with GRC during SOC2, ISO (27001, 9001, 42001), and NIS2 assessments
  • Leverage AI tools and basic coding to automate internal processes and optimize compliance workflows
  • Publish and curate compliance documentation to Docebo's trust pages using platforms like Vanta
  • Support third-party vendor risk assessments, monitor controls, and maintain dashboards to mitigate supplier risks
Requisiti fondamentali
  • 4+ years of SaaS security, audits, and compliance experience
  • Bachelor’s degree in Computer Science or related field
  • Solid knowledge of cloud environments (AWS, Azure, GCloud) and data privacy laws (GDPR, CCPA, PIPEDA)
  • Fluency with security and compliance frameworks (ISO/IEC 27001, 27017, 27018, 27701, 9001, 42001; SOC 2; PCI; NIS2; CFR21 Part 11)
  • Basic coding skills and experience with security governance platforms like Vanta and 1UP
  • Excellent written and verbal English; ability to translate technical concepts for customers
  • Proactive, adaptable problem-solver with interest in technology, business, and enterprise learning
  • Strong communication skills
  • Proactive mindset
  • Adaptability
  • AWS, Azure, GCloud proficiency
  • ISO/IEC 27001 family implementations
  • SOC 2, PCI, NIS2 familiarity